Назад
Company hidden
3 дня назад

Product Security Engineer (Fintech)

175 000 - 220 000$
Формат работы
remote (Global)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Europe
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Engineer (Fintech): Building and operating product security across stablecoin products, Solana programs, APIs, frontends, and cloud infrastructure with an accent on threat modeling, secure code review, and vulnerability management. Focus on finding authorization and business-logic vulnerabilities, securing AI and agent access, and scaling scanning, standards, and remediation workflows.

Location: Remote within North America or Europe

Salary: $175K–$220K plus equity

Company

hirify.global is a financial technology company building products and APIs for the stablecoin economy, including Solana asset management, global business accounts, and personal finance products.

What you will do

  • Review product and engineering designs, lead threat modeling, and conduct security architecture reviews.
  • Perform secure code reviews across backend services, APIs, frontends, and Solana programs, focusing on authentication, authorization, and access control.
  • Own vulnerability findings from audits, penetration tests, code scanning, and bug bounty reports through triage, remediation, and verification.
  • Build and maintain vulnerability management, bug bounty, severity, SLA, and security standards programs.
  • Improve SAST, dependency, secrets, and container scanning in CI/CD.
  • Review IAM, network controls, encryption, secrets management, cloud environments, and access for AI tools, MCP integrations, and agents.

Requirements

  • 8+ years of experience in product security, application security, or security engineering with a software engineering foundation.
  • Experience owning threat modeling and architecture reviews for complex financial or distributed systems.
  • Track record of finding critical vulnerabilities in production codebases using TypeScript, Rust, Go, or Python, including LLM- and agent-assisted workflows.
  • Experience building and operating vulnerability management or bug bounty programs, including CI/CD security scanning.
  • Deep expertise in IAM, secrets management, network controls, and container security on AWS or a comparable provider.
  • Strong written communication and the ability to work independently.

Nice to have

  • Solana program review using Rust or Anchor, audit-firm experience, or expertise in cryptography and key management.
  • Offensive testing across web and mobile, AI red teaming, or product-side SOC 2 experience.

Culture & Benefits

  • Work directly with the Head of Security, CTO, and engineering leads.
  • Operate in a small team with high standards and broad ownership.
  • Shape the product security function while remaining hands-on in engineering reviews.
  • Equity is included in the compensation package.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →